CVE-2026-72470
fs/ntfs3: resize log->one_page_buf when adopting on-disk page size
Description
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: resize log->one_page_buf when adopting on-disk page size log_replay() allocates log->one_page_buf using the page size that was chosen from the host PAGE_SIZE: log->one_page_buf = kmalloc(log->page_size, GFP_NOFS); Later, when a restart area is found, the log page size recorded on disk is adopted: t32 = le32_to_cpu(log->rst_info.r_page->sys_page_size); if (log->page_size != t32) { log->l_size = log->orig_file_size; log->page_size = norm_file_page(t32, &log->l_size, t32 == DefaultLogPageSize); } If the on-disk page size is larger than the size used for the initial allocation, log->page_size grows but one_page_buf is left at its original, smaller size. A subsequent unaligned read_log_page() then reads log->page_size bytes into the undersized scratch buffer: page_buf = page_off ? log->one_page_buf : *buffer; err = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf, log->page_size, NULL, &log->read_ahead); overflowing the allocation. This is reachable when mounting a dirty NTFS volume whose log was formatted with a page size larger than the buffer initially allocated on the mounting host (for example a 64K-log volume mounted on a host that allocated a 4K scratch buffer). Grow one_page_buf when the adopted on-disk page size exceeds the size used for the initial allocation. On krealloc() failure the original buffer is left intact and freed by the existing error path.
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 17, 2026, 6:19 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Grow one_page_buf when adopted on-disk page size exceeds initial allocation.
- Ensure krealloc() failure handling preserves original buffer.
- Apply vendor patches to the Linux kernel.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72470.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72470 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72470
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72470 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72470 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'f1422df595d69b997d23a8f11e12c528ccef7fad', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '4f129fc6f756f8541e5bff45b1804cc11b1ec712', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'c99444f6dfca893f6d310aae4a53c620f98f7b4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '5a35454179fe1041d9cd286f5d320ce0d448c12a', 'versionType': 'git'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.15'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.15', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'f1422df595d69b997d23a8f11e12c528ccef7fad', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '4f129fc6f756f8541e5bff45b1804cc11b1ec712', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'c99444f6dfca893f6d310aae4a53c620f98f7b4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '5a35454179fe1041d9cd286f5d320ce0d448c12a', 'versionType': 'git'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.15'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.15', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'f1422df595d69b997d23a8f11e12c528ccef7fad', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '4f129fc6f756f8541e5bff45b1804cc11b1ec712', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': 'c99444f6dfca893f6d310aae4a53c620f98f7b4f', 'versionType': 'git'}, {'status': 'affected', 'version': 'b46acd6a6a627d876898e1c84d3f84902264b445', 'lessThan': '5a35454179fe1041d9cd286f5d320ce0d448c12a', 'versionType': 'git'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.15'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.15', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/ntfs3/fslog.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: resize log->one_page_buf when adopting on-disk page size log_replay() allocates log->one_page_buf using the page size that was chosen from the host PAGE_SIZE: log->one_page_buf = kmalloc(log->page_size, GFP_NOFS); Later, when a restart area is found, the log page size recorded on disk is adopted: t32 = le32_to_cpu(log->rst_info.r_page->sys_page_size); if (log->page_size != t32) { log->l_size = log->orig_file_size; log->page_size = norm_file_page(t32, &log->l_size, t32 == DefaultLogPageSize); } If the on-disk page size is larger than the size used for the initial allocation, log->page_size grows but one_page_buf is left at its original, smaller size. A subsequent unaligned read_log_page() then reads log->page_size bytes into the undersized scratch buffer: page_buf = page_off ? log->one_page_buf : *buffer; err = ntfs_read_run_nb_ra(ni->mi.sbi, &ni->file.run, page_vbo, page_buf, log->page_size, NULL, &log->read_ahead); overflowing the allocation. This is reachable when mounting a dirty NTFS volume whose log was formatted with a page size larger than the buffer initially allocated on the mounting host (for example a 64K-log volume mounted on a host that allocated a 4K scratch buffer). Grow one_page_buf when the adopted on-disk page size exceeds the size used for the initial allocation. On krealloc() failure the original buffer is left intact and freed by the existing error path. Added Reference https://git.kernel.org/stable/c/2097a2537d9d1c29c0e20ed0dbf717a0ccd8f374 Added Reference https://git.kernel.org/stable/c/4f129fc6f756f8541e5bff45b1804cc11b1ec712 Added Reference https://git.kernel.org/stable/c/5a35454179fe1041d9cd286f5d320ce0d448c12a Added Reference https://git.kernel.org/stable/c/c99444f6dfca893f6d310aae4a53c620f98f7b4f Added Reference https://git.kernel.org/stable/c/f1422df595d69b997d23a8f11e12c528ccef7fad